Arbitrary Code Execution in All-in-One WP Migration and Backup Plugin by WP Engine
CVE-2026-17533
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-17533?
The All-in-One WP Migration and Backup plugin for WordPress prior to version 7.108 presents a significant security flaw in multisite environments. This vulnerability permits an administrator of a single subsite to access and execute arbitrary PHP code across the entire network. Without sufficient restrictions on the migration import feature, this issue poses a risk of unauthorized access and potential compromise of the entire multisite installation.
Affected Version(s)
All-in-One WP Migration and Backup 0 < 7.108
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.